updates to benchmark-2.3, hardening-2.3.5

This commit is contained in:
Nelson Roberts
2020-03-13 09:50:26 -07:00
parent a9b385e54b
commit 6c494d553c
2 changed files with 8 additions and 30 deletions
@@ -34,7 +34,6 @@ When performing the tests, you will need access to the Docker command line on th
The following scored controls do not currently pass, and Rancher Labs is working towards addressing these through future enhancements to the product. The following scored controls do not currently pass, and Rancher Labs is working towards addressing these through future enhancements to the product.
- 1.1.21 - Ensure that the `--kubelet-certificate-authority` argument is set as appropriate (Scored) - 1.1.21 - Ensure that the `--kubelet-certificate-authority` argument is set as appropriate (Scored)
- 2.1.8 - Ensure that the `--hostname-override` argument is not set (Scored)
### Controls ### Controls
@@ -148,7 +147,7 @@ docker inspect kube-apiserver | jq -e '.[0].Args[] | match("--profiling=false").
**Note:** This deprecated flag was removed in 1.14, so it cannot be set. **Note:** This deprecated flag was removed in 1.14, so it cannot be set.
**Result:** Pass **Result:** Not Applicable
#### 1.1.10 - Ensure that the admission control plugin `AlwaysAdmit` is not set (Scored) #### 1.1.10 - Ensure that the admission control plugin `AlwaysAdmit` is not set (Scored)
@@ -756,17 +755,9 @@ docker inspect kube-controller-manager | jq -e '.[0].Args[] | match("--root-ca-f
**Notes** **Notes**
RKE does not yet support certificate rotation. This feature is due for the 0.1.12 release of RKE. RKE handles certificate rotation through an external process.
**Audit** **Result:** Not Applicable
``` bash
docker inspect kube-controller-manager | jq -e '.[0].Args[] | match("--feature-gates=.*(RotateKubeletServerCertificate=true).*").captures[].string'
```
**Returned Value:** `RotateKubeletServerCertificate=true`
**Result:** Pass
#### 1.3.7 - Ensure that the `--address` argument is set to 127.0.0.1 (Scored) #### 1.3.7 - Ensure that the `--address` argument is set to 127.0.0.1 (Scored)
@@ -1509,15 +1500,7 @@ docker inspect kubelet | jq -e '.[0].Args[] | match("--make-iptables-util-chains
**Notes** **Notes**
This is used by most cloud providers. Not setting this is not practical in most cases. This is used by most cloud providers. Not setting this is not practical in most cases.
**Audit** **Result:** Not Applicable
``` bash
docker inspect kubelet | jq -e '.[0].Args[] | match("--hostname-override=.*").string'
```
**Returned Value:** `--hostname-override=<ipv4 address>`
**Result:** Fail
#### 2.1.9 - Ensure that the `--event-qps` argument is set to `0` (Scored) #### 2.1.9 - Ensure that the `--event-qps` argument is set to `0` (Scored)
@@ -1581,19 +1564,15 @@ docker inspect kubelet | jq -e '.[0].Args[] | match("--rotate-certificates=true"
**Returned Value:** `null` **Returned Value:** `null`
**Result:** Pass (Not Applicable) **Result:** Not Applicable
#### 2.1.13 - Ensure that the `RotateKubeletServerCertificate` argument is set to `true` (Scored) #### 2.1.13 - Ensure that the `RotateKubeletServerCertificate` argument is set to `true` (Scored)
**Audit** **Notes**
``` bash RKE handles certificate rotation through an external process.
docker inspect kubelet | jq -e '.[0].Args[] | match("--feature-gates=.*(RotateKubeletServerCertificate=true).*").captures[].string'
```
**Returned Value:** `RotateKubeletServerCertificate=true` **Result:** Not Applicable
**Result:** Pass
#### 2.1.14 - Ensure that the kubelet only makes use of strong cryptographic ciphers (Not Scored) #### 2.1.14 - Ensure that the kubelet only makes use of strong cryptographic ciphers (Not Scored)
@@ -179,7 +179,6 @@ services:
infra_container_image: "" infra_container_image: ""
cluster_dns_server: "" cluster_dns_server: ""
fail_swap_on: false fail_swap_on: false
generate_serving_certificate: true
kubeproxy: kubeproxy:
image: "" image: ""
extra_args: {} extra_args: {}